{"id":769,"date":"2013-01-01T12:33:33","date_gmt":"2013-01-01T11:33:33","guid":{"rendered":"http:\/\/diablo.craem.net\/wordpress\/?p=769"},"modified":"2013-01-01T12:33:33","modified_gmt":"2013-01-01T11:33:33","slug":"mikrotik-netflow-setup","status":"publish","type":"post","link":"https:\/\/diablo.craem.net\/?p=769","title":{"rendered":"Mikrotik &amp; Netflow setup"},"content":{"rendered":"<p>El primer post del 2013.<br \/>\nUn apunte para recordar c\u00f3mo configuraremos el netflow en una Mikrotik.<br \/>\nEntramos por telnet o winbox (prefiero telnet):<br \/>\n<code><br \/>\n# telnet 192.168.2.251<br \/>\n   mikroTik v5.22<br \/>\n   login: miuser<br \/>\n   password: xxxxxx<br \/>\n<\/code><br \/>\nEntramos en modo netflow y lo habilitamos:<br \/>\n<code><br \/>\n\/ip traffic-flow<br \/>\n \/ip traffic-flow> set enabled=yes<br \/>\n<\/code><br \/>\nY comprobamos la config:<br \/>\n<code><br \/>\n[craem@router] \/ip traffic-flow> print<br \/>\n                enabled: yes<br \/>\n             interfaces: all<br \/>\n          cache-entries: 4k<br \/>\n    active-flow-timeout: 30m<br \/>\n  inactive-flow-timeout: 15s<br \/>\n[craem@router] \/ip traffic-flow><br \/>\n<\/code><br \/>\nY ahora a\u00f1adimos el destino para los traps de netflow:<br \/>\n<code><br \/>\n[craem@router] \/ip traffic-flow target<br \/>\n[craem@router] add address=192.168.2.3:9996 version=9<br \/>\n<\/code><br \/>\nY comprobamos la config:<br \/>\n<code><br \/>\n[craem@router] \/ip traffic-flow target> print<br \/>\nFlags: X - disabled<br \/>\n #   ADDRESS               VERSION<br \/>\n 0   192.168.2.3:9996      9<br \/>\n[craem@router] \/ip traffic-flow target><br \/>\n<\/code><br \/>\nY con \u00e9sto, ya lo tenemos configurado.<br \/>\n<a href=\"https:\/\/es.wikipedia.org\/wiki\/Netflow\" title=\"Qu\u00e9 es netflow\">Netflow<\/a>, es un protocolo desarrollado inicialmente por cisco, que sirve para recolectar toda la info que pasa por los routers \/ interfaces.<br \/>\nPodr\u00ed\u00adais decir que snmp hace lo mismo, pero no es cierto. SNMP captura el volumen de tr\u00e1fico ( a lo mejor con los mibs adecuados, si), pero netflow nos desgrana en detalle ip&#8217;s origen \/ destino \/ puerto y con el programa adecuado, por ejemplo <a href=\"https:\/\/www.manageengine.com\/products\/netflow\/spanish\/index.html\" title=\"ManageEngine\"><\/a>, obtendremos unas estad\u00ed\u00adsticas interesantes, que nos puede servir, por ejemplo, para saber en qu\u00e9 gastamos nuestro ancho de banda, cantidad, etc..<br \/>\nEnjoy your netflow \ud83d\ude42<\/p>\n","protected":false},"excerpt":{"rendered":"<p>El primer post del 2013. Un apunte para recordar c\u00f3mo configuraremos el netflow en una Mikrotik. Entramos por telnet o winbox (prefiero telnet): # telnet 192.168.2.251 mikroTik v5.22 login: miuser password: xxxxxx Entramos en modo netflow y lo habilitamos: \/ip traffic-flow \/ip traffic-flow> set enabled=yes Y comprobamos la config: [craem@router] \/ip traffic-flow> print enabled: yes [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5,8],"tags":[41,107,121],"class_list":["post-769","post","type-post","status-publish","format-standard","hentry","category-linux","category-varios","tag-cisco","tag-mikrotik","tag-netflow"],"_links":{"self":[{"href":"https:\/\/diablo.craem.net\/index.php?rest_route=\/wp\/v2\/posts\/769","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/diablo.craem.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/diablo.craem.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/diablo.craem.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/diablo.craem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=769"}],"version-history":[{"count":0,"href":"https:\/\/diablo.craem.net\/index.php?rest_route=\/wp\/v2\/posts\/769\/revisions"}],"wp:attachment":[{"href":"https:\/\/diablo.craem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=769"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/diablo.craem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=769"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/diablo.craem.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=769"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}